CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2025-13339Public Exploit

Hippoo Mobile App For WooCommerce - Path Traversal (CVE-2025-13339)

PublishedDec 10, 2025
First SeenAug 19, 2026
Last Seen
Reported
CVSS7.5
wordpresscmsecommerce

Description

The Hippoo Mobile App For WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

psychologyCrowdSec Analysis

CVE-2025-13339 is a path traversal vulnerability in the Hippoo Mobile App For WooCommerce plugin for WordPress, affecting all versions up to and including 1.7.1. This flaw allows unauthenticated attackers to read arbitrary files on the server via the template_redirect() function, potentially exposing sensitive information such as configuration files, credentials, or user data.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2025-13339 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting. CrowdSec data also reveals a clear uptick in attacks involving CVE-2025-13339 over the past week. Activity is above the usual baseline, suggesting growing attention from attackers. This may reflect rising awareness, recent exploit releases, or expanded targeting efforts.

Attackers exploit this vulnerability by sending requests with the hippoo_serve query parameter containing directory traversal sequences (e.g., ../) to WordPress endpoints, such as /?hippoo_serve=../../../../wp-config.php, in order to read arbitrary files from the server.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2025-12-10
Rule Released2026-06-24
CrowdSec First Seen2026-08-19

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.